cupsd_t and sys_admin

Russell Coker <[email protected]> Sat, 05 Oct 2024 19:26:21 +1000
Newsgroups org.kernel.vger.selinux-refpolicy
Message-ID <22446657.EfDdHjke4D@cupcakke>
allow cupsd_t self:capability { chown dac_override dac_read_search fowner 
fsetid ipc_lock kill setgid setuid sys_admin sys_rawio sys_resource 
sys_tty_config };

From the refpolicy the above is the capabilities line for cupsd_t.  Why does 
it have sys_admin?  I don't think it has a legitimate need to do anything that 
needs that access.  Also sys_rawio seems dubious.

virt_rw_all_image_chr_files(cupsd_t)

Also what is the above about?

-- 
My Main Blog         http://etbe.coker.com.au/
My Documents Blog    http://doc.coker.com.au/